Create an API key
Create and protect a server-side MindCloud API key for Embedded API, MCP, and SDK setup.
Your backend uses a MindCloud API key to create end users and call server APIs. Embedded MCP also uses an API key. Never put the key in a browser page or mobile app.
Open API Keys.
Select Create API Key and give the key a name that identifies its use.
Copy the key when it appears and store it in your server's secret store. You cannot retrieve it later.
Give the key only the access your use case needs. Embedded MCP tools have different minimum access levels.
Send the key as a bearer token from your server:
Authorization: Bearer <MINDCLOUD_API_KEY>Keep the key on your server even when your frontend uses the Embedded SDK. Your server can get an end-user token and pass that token to the SDK.